Guardrails as Scapegoats: Auditing Unfaithful Safety Refusals in Tool-Augmented LLM Agents
Aarushi Singh
cs.LG, cs.AI, cs.CR
Submitted: 2026-07-21
Comments: 10 pages, 3 figures. Accepted at the ACM KDD 2026 Workshop on Evaluation and Trustworthiness of Agentic AI
Code: https://github.com/langchain-ai/langchain
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- Mind the GAP: Text Safety Does Not Transfer to Tool-Call Safety in LLM Agents
- The Llama 3 Herd of Models
- Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection
- When Refusals Fail: Unstable Safety Mechanisms in Long-Context LLM Agents
- AgentHallu: Benchmarking Automated Hallucination Attribution of LLM-based Agents
- AgentBench: Evaluating LLMs as Agents
- GPT-4 Technical Report
- Toolformer: Language Models Can Teach Themselves to Use Tools
- Towards Understanding Sycophancy in Language Models
- Language Models Don't Always Say What They Think: Unfaithful Explanations in Chain-of-Thought Prompting
- OpenAgentSafety: A Comprehensive Framework for Evaluating Real-World AI Agent Safety
- SafeToolBench: Pioneering a Prospective Benchmark to Evaluating Tool Utilization Safety in LLMs
- ReAct: Synergizing Reasoning and Acting in Language Models
- The Causal Impact of Tool Affordance on Safety Alignment in LLM Agents
Related papers
- Polynomial-Augmented Neural Networks (PANNs) with Weak Orthogonality Constraints for Enhanced Function and PDE Approximation
- AIRL-S: Unifying Reinforcement Learning and Search-Based Test-Time Scaling via Adversarial Inverse Reinforcement Learning
- Transformers as Bayesian In-Context Experimenters: Smoothness-Adaptive Efficient ATE Estimation
- Convergence issues in Relational Concept Analysis based on AOC-posets
- Beliefs Beyond Posteriors: Local-Consistency Optimisation for Bayesian Neural Networks
- Understanding Diffusion Models via Ratio-Based Function Approximation with SignReLU Networks